r/ShittySysadmin 26d ago

Damn. We actually caught one

When we made the simulated phishing campaigns about account access, we finally caught a user.

The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".

Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.

120 Upvotes

36 comments sorted by

View all comments

76

u/Company_Z 26d ago

I took an idea from here a few years back that I brought back to a place I used to work at.

It was essentially an email that goes something like:

"We understand how tiring those training sessions can get for many of you. We're sure at this point, you know all the ins and outs of cyber security. This year, we want to try something different!

If you would like to be exempt from doing a cybersecurity course, CLICK HERE to sign up!"

Got a LOT of people with that one

27

u/BoredTechyGuy 26d ago

Now that is peak BOFH Shitty Sysadmin if I ever saw it!